Laboratory-Engineered Simulation

Enterprise Email Security & Transport Assessment

Environment Stack
Microsoft 365, On-Premises Secure Mail Gateway, Managed Authoritative DNS
Category
Enterprise Security & Transport
Scope & Findings
27 Pages • 13 Findings

Executive Summary

Caldwell Harbor Trust ("Caldwell Harbor"), a regional trust bank, engaged Vaixus Technologies to conduct an independent assessment of its email transport security—the controls governing encryption-in-transit, DNS integrity, and delivery assurance for correspondence with correspondent banks, institutional trust clients, and regulatory counterparties. This engagement was scoped specifically at the request of Caldwell Harbor's Information Security Officer following an internal audit recommendation to independently verify the bank's DNSSEC, MTA-STS, and TLS reporting posture.

Caldwell Harbor's baseline sender authentication (SPF, DKIM, DMARC) is comparatively mature relative to other environments: DMARC is already enforced at p=reject, and DKIM and SPF are both correctly scoped. This assessment's findings instead concentrate on the transport-security and DNS-integrity layer beneath that authentication posture—controls that are less commonly audited but equally consequential for an institution handling wire-transfer confirmations and trust correspondence.

Vaixus identified thirteen findings. Two are rated Critical: the domain's DNS zone is not protected by DNSSEC (no Delegation Signer record is published at the registrar), and the bank's MTA-STS policy has remained in "testing" mode since deployment, providing no actual protection against TLS downgrade or interception.

This assessment finds no evidence of active compromise. Every finding is a configuration or operational-maturity gap in controls that were correctly selected but not fully completed or monitored. Vaixus recommends prioritizing the Critical findings ahead of the bank's next scheduled compliance review cycle.

Environment Overview

Caldwell Harbor operates a hybrid mail architecture: Microsoft 365 (Exchange Online) serves as the primary corporate mailbox platform, with a dedicated on-premises Secure Mail Gateway handling compliance journaling and enforcing transport-layer security policy for correspondent-bank traffic. All inbound and outbound correspondent-bank traffic is routed through this gateway.

Component / DomainPlatformFunction
caldwellharbortrust.comManaged DNSCorporate mail, brand identity, public zone
Corporate Mail PlatformMicrosoft 365 (Exchange)Employee mailboxes
Secure Mail GatewayOn-Premises HybridTLS enforcement, inbound routing
Compliance ArchiveOn-Premises StoreRegulatory recordkeeping for correspondence
mta-sts.caldwellharbortrust.comMTA-STS Policy HostPublished transport security policy
_smtp._tls.caldwellharbortrust.comTLS-RPT ConfiguredAggregate TLS negotiation reporting

Assessment Scope

In Scope
  • DNSSEC configuration and chain-of-trust validation
  • MTA-STS policy configuration, mode, and cache lifetime
  • TLS-RPT reporting configuration and review process
  • Reverse DNS (PTR) coverage for outbound relay IPs
  • Secure Mail Gateway STARTTLS negotiation behavior
  • DKIM key rotation history and DMARC reporting
Out of Scope
  • Core banking system security and transaction controls
  • Physical security of the compliance archive
  • Regulatory compliance certification or examination readiness
  • Endpoint security of employee workstations
  • Mail content, e-discovery, or records-retention policy review
  • Penetration testing of the Gateway appliance itself

Assessment Methodology

This assessment follows the Vaixus Methodology, extended with transport-security-specific validation appropriate to a regulated financial institution.

Discovery Workshop

Structured interviews with Information Security to document intended controls, audit findings, and ownership.

DNS & Trust-Chain Reconnaissance

Authoritative-record enumeration and DNSSEC chain-of-trust validation using recursive resolver testing.

Transport Security Trace Testing

Controlled SMTP sessions against the inbound relay to observe STARTTLS and MTA-STS policy behavior.

Reverse DNS and Reputation Review

PTR record validation for every outbound relay IP address, cross-referenced against gateway configuration.

Findings Synthesis

Consolidation of findings into severity-rated, business-impact-aligned recommendations.

Executive Findings Summary

Vaixus identified thirteen total findings across transport security, DNS integrity, and delivery assurance. The Critical and High severity findings requiring immediate executive attention are summarized below.

CS003-01 |DNS Integrity
DNSSEC chain of trust incomplete (no DS record at registrar)
Critical
CS003-02 |Transport Security
MTA-STS policy remains in testing mode, not enforce
Critical
CS003-03 |Delivery Assurance
3 of 6 outbound relay IPs lack matching PTR records
High
CS003-04 |Operational Risk
TLS-RPT reports generated but never reviewed
High
CS003-05 |Transport Security
Secure Mail Gateway falls back to plaintext on STARTTLS failure
High
CS003-06 |Authentication
DKIM key rotation overdue (unrotated 3+ years)
Medium

Business Impact Analysis

Foundational Trust Integrity

Because DNSSEC's chain of trust is incomplete, every DNS-published control (SPF, DKIM, DMARC, MTA-STS) is retrieved by receiving systems through an unvalidated resolution path.

Transport Security Gap

Caldwell Harbor's transport-security controls are not yet providing the protection its Information Security team believes they provide, in both the inbound and outbound direction.

Correspondent-Banking Delivery Assurance

Missing reverse DNS and unreviewed TLS reporting limit Caldwell Harbor's visibility into whether its correspondence with correspondent banks and trust clients is reliably reaching its destination today.

Remediation Strategy

Phase 1: Immediate (Weeks 1-2)

Submit DS record to registrar to complete DNSSEC chain of trust. Assign named owner to TLS-RPT review and begin active monitoring. Publish missing PTR records for 3 outbound relay IPs.

Phase 2: Near-Term (Weeks 3-6)

Reduce MTA-STS max_age and transition policy to enforce mode. Reconfigure Secure Mail Gateway to defer rather than fall back to plaintext. Rotate DKIM key. Add ruf forensic reporting address.

Phase 3: Governance and Hygiene (Weeks 7-12)

Author and adopt DMARC-failure incident-response runbook. Evaluate dedicated IP allocation for Secure Mail Gateway. Review and update SOA timing parameters. Evaluate BIMI implementation.

Verification Strategy

The following methods are utilized to confirm successful remediation and closure of identified vulnerabilities across the enterprise infrastructure.

DNSSEC ValidationDS record lookup and external DNSSEC validator confirm zone validates as "Secure" end-to-end.
MTA-STS & STARTTLSMTA-STS policy fetch and simulated downgrade trace test confirm enforcement and refusal of downgrade.
Reverse DNS (PTR)Reverse DNS lookup across all six relay IPs confirms matching, forward-confirmed hostnames.
Reporting & AuthTLS-RPT recipient access confirmed, new DKIM selector validated, and DMARC record verified for RUF.
VAIXUS-CS-003 PDF Report Cover
Representative Case Study Report

Download the Complete Case Study

This webpage summarizes the investigation logic. The complete 27-page PDF report contains full DNS trace evidence, detailed technical findings, risk prioritization tables, and structured remediation guidelines.

Download Representative Report (PDF)

Ready to begin an assessment?

Submit a request and we will review your domain, scope the engagement, and respond within one business day.

Request Assessment